LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-15505: Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-15505 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2020-15505 is a remote code execution vulnerability affecting multiple Ivanti MobileIron products, including Core & Connector, Sentry, and Monitor and Reporting Database (RDB). An attacker who can reach a vulnerable instance may be able to run code on the system, which can lead to full compromise of the MobileIron deployment and any devices or data it manages. Because MobileIron is commonly used for enterprise mobility management, successful exploitation can give an attacker a foothold inside the organization. Confirm exact product coverage and impact against the vendor advisory.

How it works

The weakness is tracked as CWE-706 (Use of Incorrectly-Resolved Name or Reference). Public detail describes an unspecified flaw in the listed Ivanti MobileIron products that allows remote code execution. In general terms for this class of issue, an attacker sends crafted input that causes the application to resolve a name or reference incorrectly, leading to unintended code execution on the server. No further exploit mechanics are provided in the available facts; treat the vulnerability as a network-reachable RCE condition on the affected MobileIron components and verify technical details only from the vendor advisory. Do not assume authentication requirements, specific protocols, or payload formats beyond what the advisory states.

Am I affected? How to find it in your systems

Ivanti MobileIron Core & Connector, Sentry, and Monitor and Reporting Database (RDB) are typically deployed as on-premises or managed appliances/servers that handle mobile device enrollment, policy enforcement, app distribution, and related monitoring. These systems often sit in DMZs or internal management networks and may be reachable from the internet or from large numbers of managed endpoints.

How to remediate

Patch first. Apply the updates published by Ivanti for the affected MobileIron products exactly as directed in the vendor advisory and in line with CISA’s required action to apply updates per vendor instructions. After patching, verify the new versions are running and that the services restart cleanly.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a remote code execution vulnerability on a mobility-management platform.

If your data may have been exposed

Actively exploited remote code execution vulnerabilities can lead to full system compromise and subsequent data theft or further lateral movement. The available facts do not document ransomware use for this CVE. If you suspect exploitation, isolate the affected hosts, preserve logs and disk images, and follow your incident-response process. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior public breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · MobileIron Multiple Products
WeaknessCWE-706
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedJul 7, 2020
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities